Vulnerabilities/

Sending a GET or HEAD request with a body crashes SvelteKit (GHSA-g5m6-hxpp-fc49)

Severity:
High

Description

In SvelteKit 2 sending a GET request with a body eg {} to a SvelteKit app in preview or with adapter-node throws Request with GET/HEAD method cannot have body. and crashes the app.

TRACE requests will also cause the app to crash. Prerendered pages and SvelteKit 1 apps are not affected.

<!–

Recommendation

Update the @sveltejs/adapter-node package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@sveltejs/adapter-node
Anything's wrong? Let us know Last updated on January 24, 2024

This issue is available in SmartScanner Professional

See Pricing